首页> 外文OA文献 >Constructing APT Attack Scenarios Based on Intrusion Kill Chain and Fuzzy Clustering
【2h】

Constructing APT Attack Scenarios Based on Intrusion Kill Chain and Fuzzy Clustering

机译:基于入侵杀戮链和模糊聚类构建APT攻击方案

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The APT attack on the Internet is becoming more serious, and most of intrusion detection systems can only generate alarms to some steps of APT attack and cannot identify the pattern of the APT attack. To detect APT attack, many researchers established attack models and then correlated IDS logs with the attack models. However, the accuracy of detection deeply relied on the integrity of models. In this paper, we propose a new method to construct APT attack scenarios by mining IDS security logs. These APT attack scenarios can be further used for the APT detection. First, we classify all the attack events by purpose of phase of the intrusion kill chain. Then we add the attack event dimension to fuzzy clustering, correlate IDS alarm logs with fuzzy clustering, and generate the attack sequence set. Next, we delete the bug attack sequences to clean the set. Finally, we use the nonaftereffect property of probability transfer matrix to construct attack scenarios by mining the attack sequence set. Experiments show that the proposed method can construct the APT attack scenarios by mining IDS alarm logs, and the constructed scenarios match the actual situation so that they can be used for APT attack detection.
机译:对互联网的APT攻击变得越来越严重,而且大多数入侵检测系统只能为APT攻击的某些步骤生成警报,无法识别APT攻击的模式。为了检测APT攻击,许多研究人员建立了攻击模型,然后将相关的IDS与攻击模型一起登录。然而,检测的准确性深深依赖于模型的完整性。在本文中,我们提出了一种通过挖掘ID安全日志构建APT攻击方案的新方法。这些APT攻击场景可以进一步用于APT检测。首先,我们通过入侵杀链链的阶段来分类所有攻击事件。然后,我们将攻击事件维度添加到模糊群集,将IDS报警日志与模糊群集相关,并生成攻击序列集。接下来,我们删除错误攻击序列以清理该集合。最后,我们使用概率传输矩阵的非缺陷属性来构建攻击序列集的攻击方案。实验表明,所提出的方法可以通过挖掘ID警报日志来构建APT攻击方案,并且构造的方案匹配实际情况,以便它们可以用于APT攻击检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号